CVE Vulnerabilities

CVE-2017-18695

Insufficiently Protected Credentials

Published: Apr 07, 2020 | Modified: Apr 08, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a users credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654 (January 2017).

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Android Google 4.4 (including) 4.4 (including)
Android Google 5.0 (including) 5.0 (including)
Android Google 5.1 (including) 5.1 (including)
Android Google 6.0 (including) 6.0 (including)
Android Google 7.0 (including) 7.0 (including)

Potential Mitigations

References